The UK cryptoasset regulatory regime is entering its most significant transition since Money Laundering Regulations (MLR) registration was introduced in 2020. From 30 September 2026, the Financial Conduct Authority (FCA) will accept applications for full FSMA authorisation under the new cryptoasset regime, and existing MLR-registered firms will not be automatically converted. Every firm intending to continue carrying on regulated UK cryptoasset activities will need to satisfy the full FSMA threshold conditions and the detailed rules applicable to its business.
This guide explains the timetable, permissions, capital, governance, application content and preparation strategy. For firms that intend to issue a UK stablecoin, the specific issuer requirements are set out separately in our FCA stablecoin authorisation guide.
Cryptoasset authorisation timetable at a glance
| Milestone | Date |
|---|---|
| FCA authorisation gateway opens | 30 September 2026 |
| Main application window closes | 28 February 2027 |
| New cryptoasset regulatory regime commences (expected) | 25 October 2027 |
| MLR to FSMA transition for existing firms | No automatic conversion — new application required |
| Regulatory basis | Financial Services and Markets Act 2000 (FSMA) |
| Conduct standards | FCA Handbook, Consumer Duty, SM&CR, operational resilience |
The application window is limited and the FCA has been explicit that it will not accelerate late applications. Firms should therefore treat 28 February 2027 as a regulatory deadline rather than a commercial target.
Why is the FCA cryptoasset regime changing?
The current framework treats cryptoasset businesses as regulated only for AML purposes. That framework was never designed to address prudential resources, governance, customer protection, operational resilience or the specific risks associated with custody, trading, staking or stablecoin issuance.
The new regime moves cryptoasset activities into full FSMA authorisation. Authorised firms will operate under the FCA Handbook, the Senior Managers and Certification Regime and, where relevant to their customer base, Consumer Duty. This is a substantively higher standard than the UK cryptoasset AML registration that most firms currently hold.
Which cryptoasset activities will require FCA authorisation?
The new regime covers, among others:
- Operating a qualifying cryptoasset trading platform
- Safeguarding cryptoassets on behalf of customers
- Dealing in cryptoassets as principal or as agent
- Arranging cryptoasset transactions
- Certain cryptoasset lending and borrowing activities
- Qualifying cryptoasset staking
- Issuing qualifying stablecoins in the UK
A single business may require several permissions depending on the services it provides. An exchange that also custodies customer assets and arranges transactions would typically seek permissions covering each activity. Firms should map their actual customer journey against the regulated activities rather than assuming that a single "exchange" permission will cover the entire business model.
Our licensing and authorisation team can assess which specific permissions are needed for a given operating model, and the UK Cryptoasset Service Provider (CASP) licence page sets out the general perimeter for cryptoasset businesses operating in the UK.
Does an existing MLR registration convert automatically?
No. There is no automatic conversion from MLR registration to FSMA authorisation. Existing registered firms must submit a new application and satisfy the FCA that they meet the full requirements of the new regime.
Existing AML systems, regulatory history and operational track record will be relevant to the FCA's assessment, but authorisation also introduces prudential resources, governance under SM&CR, conduct obligations, Consumer Duty where applicable, operational resilience and the activity-specific requirements attached to custody, trading, staking and stablecoin issuance.
Registered firms that assume their existing framework will simply "roll over" are likely to discover material gaps late in the application cycle. Boards should commission a comparison of the current operating model against the new FSMA requirements well before the gateway opens.
Why should firms apply early?
The FCA has indicated that applications will be assessed broadly in the order received and has encouraged firms to apply as early as possible within the main window. There is also a transitional protection for existing MLR-registered firms that submit a complete application within the main window: those firms may generally continue their existing regulated cryptoasset business under the current framework while the application is determined.
This protection should not be treated as a reason to delay. A weak or incomplete application can be delayed, rejected or ultimately refused. For an existing cryptoasset business, the application timetable should therefore work backwards from the intended submission date. Governance changes, capital raising, senior management appointments, policies, financial forecasts and operational improvements may all need to be completed before the application is ready.
What happens if a crypto firm applies late?
Firms can submit an application after 28 February 2027, but the consequences can be materially different. The FCA has stated that it will not accelerate late applications simply because a business failed to apply during the main window.
Where an existing firm applies late and has not obtained the necessary authorisation when the new regime begins, applicable transitional arrangements may restrict the business it can conduct while the application is determined. The firm may be limited in its ability to enter into new contracts or onboard new UK customers. A firm that does not apply at all must run off its regulated UK cryptoasset business before the new regime begins. Continuing regulated business without the required permission risks breaching the FSMA general prohibition.
For an established crypto business, missing the main application window can therefore become a commercial continuity issue rather than merely an administrative delay.
What will the FCA assess in a cryptoasset authorisation application?
The FCA will assess whether the applicant satisfies and can continue to satisfy the threshold conditions and the detailed rules applicable to the cryptoasset activities for which permission is sought.
The starting point is the business model. The application must explain clearly what products and services the firm provides, which cryptoassets are involved, who its customers are, how transactions are executed, where assets and funds are held, which third parties are used and how the business generates revenue. The requested permissions must align precisely with those activities.
Governance will be another central area. The FCA will expect clear responsibility at board and senior management level, appropriate skills and experience, effective challenge, conflicts management and sufficient regulatory oversight. The Senior Managers and Certification Regime will apply to authorised cryptoasset firms, bringing greater individual accountability for key regulatory responsibilities.
The FCA will also assess financial resources, operational resilience, outsourcing, financial crime, customer treatment, complaints, Consumer Duty where applicable, technology risk and the controls specific to activities such as custody, trading, staking or stablecoin issuance. The application needs to describe a business that is ready to operate compliantly rather than one that intends to build the required framework after authorisation.
What documents will a cryptoasset authorisation application require?
The exact requirements depend on the business model and permissions sought, but a substantial application will require considerably more than an application form.
A detailed regulatory business plan should explain the business model, ownership, products, target customers, regulated activities, revenue model, transaction flows, governance arrangements and growth strategy. The FCA should be able to understand how the business operates without reconstructing the model from inconsistent documents.
Applicants will also need an appropriate governance and compliance framework. This can include senior management arrangements, financial crime controls, risk management, conflicts policies, complaints procedures, Consumer Duty arrangements, operational resilience, outsourcing oversight, business continuity, wind-down planning and regulatory reporting processes.
Activity-specific documentation will depend on the permissions sought. A custodian will need detailed arrangements for safeguarding client cryptoassets, key management, reconciliation and asset return. A trading platform will require appropriate market, execution, admission, conflicts and operational controls. A stablecoin issuer will need a comprehensive backing-asset, redemption, safeguarding and disclosure framework — the detail is covered in our stablecoin authorisation guide.
Financial forecasts and prudential calculations must align with the business plan. Forecast transaction volumes, customer numbers, staffing, technology expenditure and revenue assumptions should be credible and consistent across the application.
Capital and prudential requirements
The new regime introduces a formal prudential framework for regulated cryptoasset firms. The amount of capital required depends on the activities carried on and the scale and risk profile of the business.
The FCA has established activity-based permanent minimum requirements together with a wider own funds framework. Depending on the firm, the minimum own funds requirement can be driven by the permanent minimum requirement, fixed overheads requirement or applicable K-factor requirements, with the highest relevant amount determining the regulatory minimum.
The headline minimum capital figure should therefore not be treated as the firm's final capital requirement. A larger or more complex business can be required to maintain significantly more own funds than the activity-specific floor.
Applicants must also consider liquidity and wind-down resources. The FCA expects firms to have sufficient financial resources not only to operate normally but also to withstand stress and, if necessary, exit the market in an orderly way without creating avoidable harm for customers.
Senior management and governance
Full FSMA authorisation places substantially greater emphasis on individual accountability than the current MLR registration framework. The Senior Managers and Certification Regime will apply to authorised cryptoasset firms. Relevant senior management functions, prescribed responsibilities and governance arrangements will need to be mapped appropriately to the firm's organisational structure.
The FCA will assess whether the proposed leadership team has the experience, capacity and authority required to oversee the business. A rapidly growing crypto firm cannot rely solely on technical founders while treating regulated governance as a compliance function sitting beneath the commercial organisation.
Responsibility for financial crime, customer protection, prudential risk, operational resilience, custody and other material areas should be clear at senior level. Management information should allow the board and senior managers to understand the risks being taken and whether regulatory controls are functioning effectively.
Consumer Duty and conduct requirements
Authorised cryptoasset firms serving retail customers will operate within a much broader conduct framework than currently applies under AML registration. Relevant firms will need to consider product design, target markets, price and value, customer understanding and customer support. Disclosures and risk warnings remain important, but Consumer Duty requires firms to assess the actual outcomes customers receive rather than treating compliance as a disclosure exercise.
This is particularly significant for complex products where customers may not fully understand custody arrangements, execution models, staking risks or the consequences of firm failure. Firms should be able to identify foreseeable harm and demonstrate how product design and distribution reflect the intended customer base.
Complaints handling requirements will also become more significant, including access to the Financial Ombudsman Service for eligible complaints relating to regulated activities.
Operational resilience and technology risk
Cryptoasset businesses depend heavily on technology, third-party infrastructure and digital networks, making operational resilience a central part of the new framework. Authorised firms will need to identify important business services, understand the people, processes, technology and information supporting those services and demonstrate appropriate resilience during disruption.
Third-party dependence also needs careful management. Cloud providers, custody technology, blockchain infrastructure, liquidity venues and outsourced compliance or operational functions can create material dependencies, but regulatory responsibility remains with the authorised firm.
The FCA will expect credible incident management, business continuity and recovery arrangements rather than generic technology policies that do not reflect the actual operating model.
Should firms use the FCA Pre-Application Support Service?
The FCA has introduced a Pre-Application Support Service for firms preparing to enter the new cryptoasset regime. It provides an opportunity to explain the proposed business model, discuss the authorisation process and understand the FCA's expectations before filing.
The meeting is optional and does not provide regulatory advice or guarantee authorisation. Firms requesting engagement should provide meaningful information about their products, customers, business model and analysis of the regulated activities they intend to perform. For complex applications, the pre-application process can be useful where genuine perimeter, structural or permission questions would benefit from early FCA discussion.
What should crypto firms do now?
Firms intending to apply should begin with a detailed regulatory gap assessment comparing the current operating model against the new FSMA requirements. This should identify the work required across permissions, governance, prudential resources, customer treatment, financial crime, operational resilience and activity-specific controls.
The board should then agree a realistic implementation plan with clear ownership and deadlines. Where changes to management, capital, technology, custody structures or business processes are required, these should be completed early enough to be evidenced within the application. The application itself should operate as one coherent regulatory case: the business plan, financial forecasts, policies, governance documents and application responses should describe the same business and use consistent assumptions.
Firms should not treat 28 February 2027 as the target submission date. Applying earlier gives the FCA more time to assess the application and reduces the commercial risk of approaching commencement without a determined application.
How Regulatory Counsel can help
Regulatory Counsel supports cryptoasset firms through the complete FCA authorisation process, from initial perimeter analysis and application strategy through to submission, FCA questions and determination.
We assess the proposed business model and determine which regulated activities and permissions apply, then carry out a gap analysis against the new FCA requirements. Where the existing framework needs strengthening, we help develop the governance, prudential, compliance and operational arrangements required before application.
Our work can include the regulatory business plan, application forms, financial forecasts and prudential calculations, governance framework, Consumer Duty, financial crime, operational resilience, wind-down planning and the activity-specific policies and procedures required for custody, trading, staking, stablecoin issuance and other regulated cryptoasset services.
For existing MLR-registered firms, we manage the transition from registration to full FSMA authorisation. For firms already authorised under FSMA, we support Variation of Permission applications to add the required cryptoasset activities.
The application window is limited and the standard is materially higher than MLR registration. Contact Regulatory Counsel to discuss your FCA cryptoasset authorisation strategy or application.
Frequently Asked Questions
The FCA application period opens on 30 September 2026 and the main application window closes on 28 February 2027. The new cryptoasset regulatory regime is expected to commence on 25 October 2027. Firms intending to continue regulated UK cryptoasset activities should prepare well before the gateway opens so that governance, capital, policies and supporting documentation are ready for submission.
No. There is no automatic conversion from MLR registration to FSMA authorisation. Existing registered firms must submit a new application and satisfy the FCA that they meet the full requirements of the new regime. Their existing AML systems and regulatory history will be relevant, but authorisation also introduces prudential, governance, conduct, Consumer Duty, operational resilience and other requirements.
The regime covers activities including operating qualifying cryptoasset trading platforms, safeguarding cryptoassets, dealing as principal or agent, arranging cryptoasset transactions, certain lending and borrowing activities, qualifying cryptoasset staking and issuing qualifying stablecoins. A single business may require several permissions depending on the services it provides.
A late application can still be submitted, but the FCA will not accelerate it because the firm missed the main window. If the business has not obtained authorisation by commencement, applicable transitional restrictions may limit its ability to onboard new UK customers or enter into new contracts while the application is determined.
There is no single guaranteed determination period for every cryptoasset application. Timing will depend on the complexity and quality of the application, the permissions sought and whether the FCA requires further information. Firms should therefore focus on submitting a complete and internally consistent application as early as practicable.